05/12/14 17:00:34 R2b6XWwm0
>>540
もしTigerでの設定と同じにしたいってんなら、差は下記。
20000 deny icmp from any to me in icmptypes 8 ←ステルスモード
20310 allow udp from any to any dst-port 53 in ←これ以降UDPブロック
20320 allow udp from any to any dst-port 68 in
20321 allow udp from any 67 to me in
20322 allow udp from any 5353 to me in
20340 allow udp from any to any dst-port 137 in
20350 allow udp from any to any dst-port 427 in
20360 allow udp from any to any dst-port 631 in
20370 allow udp from any to any dst-port 5353 in
22000 allow udp from any to any dst-port 123 in
30510 allow udp from me to any out keep-state
30520 allow udp from any to any in frag
35000 deny udp from any to any in
ログ採取は、ルール番号: 12190、20000、35000の deny を deny log にする。
それと、sysctlで -w net.inet.ip.fw.verbose=1 しとく。
ログはsystem.logに出たと思う。それもTigerに合わせるならipfw.logに変える。
そこまでやる必要はないと思うけど。